PCI DSS Gap Analysis

|
|
|
PUBLISHED on
04
August
2022
SUMMARY

Who is the Gap Analysis Aimed At?

URM’s PCI DSS gap analysis service is aimed at those organisations which are looking to benchmark their current corporate information security practices (relating to payment card data) against the Standard and understand their readiness for a c

The gap analysis is often the first step of a PCI DSS project and provides you with a roadmap for achieving compliance.

This service will typically involve one of URM’s QSAs spending time on your site or meeting remotely with those individuals responsible for:

  • The PCI DSS programme
  • Network administration and cardholder systems
  • Developing company policies and procedures

Focus of Gap Analysis

URM’s QSA will assess your organisation’s practices against the 12 high-level PCI DSS requirements as follows:

  1. Install and maintain network security controls
  2. Apply secure configurations to all system components
  3. Protect stored account data
  4. Protect cardholder data with strong cryptography during transmission over open, public networks
  5. Protect all systems and networks from malicious software
  6. Develop and maintain secure systems and software
  7. Restrict access to system components and cardholder data by business ‘need to know’
  8. Identify users and authenticate access to system components
  9. Restrict physical access to cardholder data
  10. Log and monitor all access to system components and cardholder data
  11. Test security of systems and networks regularly
  12. Support information security with organisational policies and programs

Gap Analysis Outputs

The key output from our PCI DSS gap analysis service will be a report that includes:

  • A definition of your cardholder data environment (CDE) and in-scope business processes, applications, devices, networks, facilities and service providers
  • An assessment of how closely your organisation meets each of the PCI DSS requirements
  • Recommendations for reducing the scope of the CDE, where applicable, thus reducing the potential cost of compliance
  • Detailed recommendations for remediating any areas of non-compliance
  • Advice regarding your organisation's best options for achieving PCI DSS compliance quickly and cost-effectively, drawing upon our QSAs’ experience working with similar organisations.

Are you looking for help preparing for a PCI DSS assessment?

As a PCI QSA, URM can assist you with a range of services, including conducting gap analyses, helping you reduce your CDE scope and conducting penetration tests.
Thumbnail of the Blog Illustration
Information Security
Published on
9/8/2022
PCI DSS: Pros and Cons of Outsourcing

In this blog, we address one of the big questions facing organisations which accept payment cards....

Read more
Thumbnail of the Blog Illustration
Information Security
Published on
10/3/2025
PCI SSC Announces Changes to the SAQ A

URM’s blog explains the recent update to PCI DSS SAQ-A that has resulted in the removal of 2 new v4 requirements & the addition of new eligibility criteria.

Read more
Thumbnail of the Blog Illustration
Information Security
Published on
22/3/2024
Common Questions When Preparing to Transition to PCI DSS v4.0

URM’s blog answers key questions about the practicalities of PCI DSS v4.0 transition assessments and how you can best prepare for a successful v4.0 transition.

Read more
Thank you this was really helpful, I am looking forward to the Cyber Essentials webinar.
Webinar 'How to Develop and Maintain Robust Business Continuity Plans'
contact US

Let us help you

Let us help you in your compliance journey by completing the form and letting us know how we can best support you.